Exaforce's latest tool expands AI security monitoring beyond Claude, utilizing existing data to identify risks and control AI agent behavior.

Exaforce is transforming how enterprise security teams monitor AI agents by leveraging existing security telemetry instead of requiring new endpoint sensors. This innovative approach allows organizations to discover and track AI applications more efficiently.
By integrating usage data from prominent AI platforms with insights from endpoints, cloud services, SaaS, and code repositories, Exaforce AI Security can pinpoint risks, detect unusual activities, and effectively respond to threats. Co-founder Ariful Huq emphasized that their solution utilizes data already collected by Security Operations Centers (SOCs) to catalog every AI tool, associating each with its respective user, device, and permissions. This helps in identifying potential misuse on a granular level and enables containment through established security measures.
The recent upgrade extends beyond Claude's Compliance API, which Exaforce introduced in June. Now, it includes monitoring capabilities for other model providers like OpenAI, Gemini, and Microsoft Copilot, along with OAuth-connected applications. This interconnected approach allows for the correlation of AI agent actions with existing SOC data, providing clarity on what an AI agent is executing, who is utilizing it, and whether it poses any security risks.
According to Osterman Research Principal Analyst Michael Sampson, Exaforce is tuned into the right signals by recognizing that AI agents operate across various devices, data sources, and identities. He pointed out that relying solely on conventional solutions like Endpoint Detection and Response (EDR), Identity Access Management (IAM), or SaaS security tools may fall short. Sampson suggests that a comprehensive view of behaviors and actions across the entire spectrum is critical in determining what's permissible.
What's compelling about Exaforce's solution is its lack of requirement for new gateways, browser add-ons, or endpoint agents to gather data. Instead, it consolidates information from EDR systems, audit logs from model providers, and productivity tools, painting a detailed picture of AI agent activity.
Proactive Measures Beyond Monitoring
Exaforce is not confined to passive observation; it actively responds to detected threats using existing EDR frameworks, identity management, and model-provider administrative controls. This capability allows it to execute various actions, such as terminating sessions, revoking API keys, isolating compromised devices, or stopping problematic agent processes.
In contrast to Exaforce's approach, competitors are employing distinct strategies to address AI security concerns. For instance, Palo Alto Networks’ Prisma AIRS 3.0, launched in March, focuses on centralizing visibility of AI agents and enforcing policies to protect the overall AI lifecycle. Meanwhile, SentinelOne’s Prompt AI Agent Security tackles risk assessment and enforcing least privilege access while also managing potentially malicious interactions. CrowdStrike's Falcon Guardian, released in September, introduced new endpoint software tailored for AI detection and response.
While many of these tactics center on discovering AI agents, a March 2026 survey by the Cloud Security Alliance revealed that 68% of organizations struggle to differentiate between human and AI-agent activities. Added to this complexity, 74% of organizations admitted that AI agents often had broader access than necessary, with 52% admitting that these agents inherited permissions meant for human users.
This multifaceted challenge highlights the need for a versatile solution that goes beyond basic tracking to actively manage AI agent security. Analyst Avivah Litan critiqued that most current offerings provide limited intervention capabilities and often lack in-line blocking or remediation options. She argues that effective solutions must be capable of identifying authorized and unauthorized agents across diverse environments, mapping ownership of both human and AI entities, and enforcing policies even when agents operate outside their originating platforms.
Exaforce's Huq believes their system is progressing toward this objective. The Exaforce AI Security solution enriches its contextual understanding of AI and agent data, thus better distinguishing between human identities and those AI agents that operate with inherited permissions.
Currently, Exaforce AI Security is available on the Exaforce Agentic SOC platform, either for self-management or through Exaforce's Managed Detection and Response (MDR) services.
Discussion
Sign in to join the discussion.